Skip to content

Weechat

v4.9.4 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 7d Editors & IDEs
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

c chat client extensible irc javascript
+8 more
lua perl php python ruby scheme scripting tcl

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 7d

Version v4.9.4 of Weechat patches a critical authentication bypass vulnerability and resolves several bug issues.

Why it matters: The release fixes an authentication bypass (severity 95) that could allow unauthorized access; all deployments using plain password hash authentication should upgrade immediately.

Summary

AI summary

Updates core, logger, and https://github.com/weechat/weechat/security/advisories/GHSA-68ff-gq39-pqjm across a mixed release.

Changes in this release

Security Critical

Patches authentication bypass with plain password hash algorithm

Patches authentication bypass with plain password hash algorithm

Source: llm_adapter@2026-07-19

Confidence: high

Performance Medium

Improves speed of displaying long words in chat area

Improves speed of displaying long words in chat area

Source: llm_adapter@2026-07-19

Confidence: high

Bugfix High

Fixes infinite loop when read_marker_string width is zero

Fixes infinite loop when read_marker_string width is zero

Source: llm_adapter@2026-07-19

Confidence: high

Bugfix High

Fixes integer overflow in size calculation for ${hide:...} and ${base_encode:...} expansions

Fixes integer overflow in size calculation for ${hide:...} and ${base_encode:...} expansions

Source: llm_adapter@2026-07-19

Confidence: high

Full changelog

Fixed

Changed

  • core: improve speed of display of long words in chat area (#2336)

Fixed

  • core: fix infinite loop when option weechat.look.read_marker_string is set to a string with a width of zero (#2337)
  • core: fix integer overflow in size calculation when evaluating "${hide:...}" and "${base_encode:...}" (#2335)
  • logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators (#2340)
  • relay: fix authentication bypass with the "plain" password hash algorithm (GHSA-68ff-gq39-pqjm)

Download

https://weechat.org/download/weechat/4.9.4/

Security Fixes

  • GHSA-68ff-gq39-pqjm — relay authentication bypass with "plain" password hash algorithm

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Weechat

Get notified when new releases ship.

Sign up free

About Weechat

Fast, light and extensible chat client.

All releases →

Beta — feedback welcome: [email protected]